Hi zellex, welcome to DaniWeb. :)
To begin with, please do the following:
You will need to close/quit all web browser programs and disconnect from the Internet for some of the following, so you should print out the following instructions or save them into a text file with Notepad.
* Download the 14-day free trial verison of ewido anti-malware .Install ewido anti-malware
When installing, under "Additional Options" uncheck..Install background guard
Install scan via context menu
Launch ewido, there should be an icon on your desktop, double-click it.
The program will now open to the main screen.
When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
You will need to update ewido to the latest definition files.On the left hand side of the main screen click update.
Then click on Start Update.
The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display ("Update successful" )
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates
Don't run a scan with ewido yet; just close the program once the updates are installed.
* Close all open/running programs, especially Internet Explorer.
Run HijackThis again, put a check mark in the boxes to the left of the following entries, and then click the "Fix checked" button. Close HJT after the fixes have completed:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://by7fd.bay7.hotmail.msn.com/cg...5635eaa8f2c639 (obfuscated)
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [d12a346d.exe] C:\WINDOWS\system32\d12a346d.exe
O4 - HKCU\..\Run: [d12a346d.exe] C:\Documents and Settings\Cathy\Local Settings\Application Data\d12a346d.exe
* Using your Add/Remove Programs control panel, uninstall the "Viewpoint" software package.
* Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up) and:Open up Ewido
Click on scanner
Click on Complete System Scan and the scan will begin.
You will be prompted to clean the first infection.
Select "Perform action on all infections", then proceed.
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Click Save report.
Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware.
* Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".
Look for the following file, and delete it if it still exists:
C:\Documents and Settings\Cathy\Local Settings\Application Data\d12a346d.exe
* Empty your Recycle Bin and reboot normally.
* Run HJT again and post the new log. Also post the scan report that ewido generated.